keskiviikko 6. lokakuuta 2010

stuxnet could adjust motors, conveyor belts, pumps. It could stop a factory. With right modifications, it could cause things to explode.

driver was signed with a certificate stolen from Realtek Semiconductor Corp.
modified variant with a certificate stolen from JMicron Technology Corporation
Q: How is that possible?
A: Good question.
Q: How could governments get something so complex right?
A: Trick question. Nice. Next question. Google was named Aurora after this path was found inside one path in Stuxnet is: \myrtus\src\objfre_w2k_x86\i386\guava.pdb
Q: How does Stuxnet know it has already infected a machine?
A: It sets a Registry key with a value "19790509" as an infection marker
on that date a Jewish-Iranian businessman called Habib Elghanian was executed in Iran. He was accused to be spying for Israel. The current versions have a "kill date" of June 24, 2012. It will stop spreading on this date.

Ei kommentteja:

Twitter Updates

    follow me on Twitter

    Oma blogiluettelo

    https://www.facebook.com/valtioopinseniorit

    Blogiarkisto